Vulnerability MAL-2026-17472
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 day ago
October 04, 2026 at 07:09 PM UTC
Malicious code in anthropic-sdk (PyPI)
0.1.0
0.1.0
Summary
Malicious code in anthropic-sdk (PyPI)
Details
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-10-anthropic-sdk
Reasons (based on the campaign):
-
impersonation
-
Downloads and executes a remote malicious script.
-
The package contains code to detect if it is running in a sandbox environment.
-
obfuscation
-
exfiltration-credentials
-
files-exfiltration
-
exfiltration-env-variables
-
exfiltration-ssh-keys
Impacted packages
Timeline
Published
1 day ago
October 04, 2026 at 07:09 PM UTC
Last Modified
20 hours ago
October 05, 2026 at 04:15 AM UTC